SOC – Latest CVEs
Live vulnerability feed from NVD
OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa…
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau…
RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form…
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t…
Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to c…
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. …
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that…
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where…
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to …
OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th…
| CVE | Description | Severity | Published | Last Modified |
|---|---|---|---|---|
| CVE-2026-34505 | OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook s… | MEDIUM | 2026-03-31 12:16:30 UTC | 2026-07-24 22:10:00 UTC |
| CVE-2026-34506 | OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended auth… | MEDIUM | 2026-03-31 12:16:30 UTC | 2026-07-24 22:10:00 UTC |
| CVE-2026-34155 | RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cau… | MEDIUM | 2026-03-31 14:16:11 UTC | 2026-07-24 22:10:00 UTC |
| CVE-2026-34156 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Sc… | CRITICAL | 2026-03-31 14:16:12 UTC | 2026-07-24 22:10:00 UTC |
| CVE-2026-33276 | Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbit… | MEDIUM | 2026-03-31 15:16:14 UTC | 2026-07-24 21:10:00 UTC |
| CVE-2026-33576 | OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network f… | MEDIUM | 2026-03-31 15:16:14 UTC | 2026-07-24 21:10:00 UTC |
| CVE-2026-33577 | OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to appro… | HIGH | 2026-03-31 15:16:14 UTC | 2026-07-24 21:10:00 UTC |
| CVE-2026-33578 | OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies si… | MEDIUM | 2026-03-31 15:16:14 UTC | 2026-07-24 21:10:00 UTC |
| CVE-2026-33579 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core appr… | CRITICAL | 2026-03-31 15:16:14 UTC | 2026-07-24 21:10:00 UTC |
| CVE-2026-33580 | OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak … | MEDIUM | 2026-03-31 15:16:15 UTC | 2026-07-24 21:10:00 UTC |